You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过AppSync评估解析器代码时能否指定认证类型?

解决AWS AppSync解析器模板评估时的Cognito身份字段不识别问题

问题分析

你遇到的错误根源在于:Boto3的evaluate_mapping_template/evaluate_code默认将传入的identity解析为Lambda认证类型的身份对象(LambdaAuthIdentity),而该类型仅支持resolverContext字段,无法识别Cognito用户池身份特有的username等字段。

解决方案

要让评估函数正确识别Cognito用户池类型的身份,需要在identity对象中添加__typename字段,明确指定其类型为CognitoUserPoolsIdentity——这是AppSync内部用来区分不同认证类型身份的标识字段。

修改后的上下文示例

context = {
    "arguments": {},
    "stash": {},
    "source": {},
    "result": {},
    "identity": {
        "__typename": "CognitoUserPoolsIdentity",
        "username": "user",
        # 可选:可按需添加其他Cognito身份字段,如sub、email等
        "sub": "12345678-1234-1234-1234-1234567890ab",
        "email": "user@example.com"
    },
    "request": {},
}

对应的基础解析器模板示例

{
    "version": "2017-02-28",
    "payload": {
        "username": "$ctx.identity.username"
    }
}

验证结果

使用修改后的上下文调用evaluate_mapping_template,就能正常解析ctx.identity.username字段,不会再出现字段不识别的错误。

补充说明

AppSync的不同认证类型对应不同的身份类,通过__typename字段可明确指定身份类型:

  • Cognito用户池:CognitoUserPoolsIdentity
  • Lambda认证:LambdaAuthIdentity
  • IAM认证:IAMIdentity

内容的提问来源于stack exchange,提问作者Vince

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 22:12:14